Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-16317 Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard indi… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.5 CVE-2026-65065 Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The se… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.2 CVE-2026-64613 Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created … No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-59147 Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach… No fix yet Fix from $2,3002026-07-21 MEDIUM 6.3 CVE-2026-59143 Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_conta… No fix yet Fix from $1,6002026-07-21 HIGH 7.8 CVE-2026-59146 Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sp… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.1 CVE-2026-59145 Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The a… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-59144 Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time … No fix yet Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-56852 A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-50759 An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints wi… No fix yet Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-50758 Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter Mitigation only Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-46600 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. No fix yet Fix from $1,9502026-07-21 HIGH 7.8 CVE-2026-50757 Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-… No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-50756 An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-50755 An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value No fix yet Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-15957 Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.1 CVE-2026-59142 Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The atta… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59141 Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The att… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59140 Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. … No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59139 Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The… Mitigation only Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2016-20096 Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute ar… No fix yet Fix from $2,3002026-07-21 MEDIUM 6.5 CVE-2026-56577 HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. Dryice Mycloud No fix yet Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-47411 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling wo… No fix yet Fix from $1,6002026-07-21 HIGH 7.8 CVE-2026-16493 A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone com… No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-44907 A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to exce… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.3 CVE-2026-16451 A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the f… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-15342 Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.3 CVE-2025-68640 The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices an… No fix yet Fix from $1,6002026-07-21 HIGH 8.7 CVE-2026-15724 In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal … No fix yet Fix from $1,9502026-07-21 HIGH 8.2 CVE-2026-15432 When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows… No fix yet Fix from $1,9502026-07-21